Astaroth, also widely tracked as Guildma, is a long-running Latin American banking malware operation focused primarily on Brazilian users and financial fraud. It is known for stealthy, multi-stage delivery chains, in-memory execution, credential and session theft, and flexible command-and-control mechanisms. The malware has been observed targeting Brazilian financial institutions, digital payment services, cryptocurrency exchanges, and cryptocurrency wallet platforms. Astaroth commonly appears at the end of layered infection chains that use script-based loaders, living-off-the-land execution, and staged payload retrieval to reduce detection. Recent activity has shown the malware delivered through WhatsApp-themed social engineering and propagated via hijacked or reused authenticated WhatsApp Web sessions, with delivery infrastructure associated with the SORVEPOTEL worm. In these campaigns, intermediate loaders used PowerShell, MSI packages, and AutoIt components before decrypting and manually mapping the final payload into a hollowed system process for memory-resident execution. Operationally, Astaroth functions as a banking trojan and backdoor with host reconnaissance, credential theft, and session theft capabilities. It gathers system telemetry, remains resident in memory, and can delay or tailor activity until financial activity is detected. Its command-and-control has included both traditional web-based telemetry and mailbox-based IMAP communications, reflecting an emphasis on resilience and stealth. The malware has also been reported using GitHub to improve operational resilience. The actor’s tradecraft includes defense evasion through obfuscation, fragmented loader logic, in-memory execution, process hollowing, and abuse of trusted platforms and legitimate tooling. High-confidence reporting supports its role as a financially motivated threat centered on banking and cryptocurrency theft rather than espionage or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Astaroth (Guildma) is conducting financially motivated malware campaigns targeting Latin American financial institutions and cryptocurrency platforms. The group uses multi-stage, in-memory malware delivery chains, leveraging social engineering via WhatsApp, and advanced evasion techniques such as process hollowing and IMAP-based C2.
Astaroth is a banking trojan targeting Brazilian users via WhatsApp phishing lures.
Astaroth is a banking trojan known for abusing GitHub to increase its resilience and evade detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.